CVE-2021-44228/45046/45104/45105, problem log4j jar files exists in oracle home
Oracle has already provide fix for these files, given as bellow,
The vulnerabilities CVE-2021-44228, CVE-2021-45046 ("Log4j" jar files) doesn't affect the database and the client. You can validate this information the below document:
Impact of December 2021 Apache Log4j Vulnerabilities on Oracle Products and Services (CVE-2021-44228, CVE-2021-45046) ( Doc ID 2827611.1 )
It is mentioned that oracle spatial and graph component have these vulnerabilities, specifically it is applicable to the 12.2, 18.x and 21.x. But they are not reported for 19c.
We are currently using 12.2 and 19c standard database edition, and both oracle version contains vulnerable jar files, but still oracle mentioned that only 12.2 is affected and 19c is not affected. How is this considered while finding exploitable vulnerability.